HRS

Human Resources

Domain definition — mapping in progress (source: AI Controls Matrix (AICM) Introductory Guidance).

15

Control objectives

1

Skills

1

Cross-cutting

—

Objectives fitted

AISMM maturity context

Governance · Foundational domain

L1 InitialL2 RepeatableL3 DefinedL4 CapableL5 Efficient

A lens, not a partition. How AISMM adoption works →

Control objectives

The exact things this domain must do. Each carries an authoritative crosswalk to 8 external control sets (Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0). Fitted skills are drawn from the pool below as fits are evidenced.

Background Screening Policy and ProceduresHRS-01

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 15 steps
Application Provider — 7 steps
Model Provider — 8 steps
Orchestrated Services Provider — 8 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Acceptable Use of Technology Policy and ProceduresHRS-02

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 10 steps
Application Provider — 7 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Clean Desk Policy and ProceduresHRS-03

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 1 step
Cloud Service Provider — 11 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Remote and Home Working Policy and ProceduresHRS-04

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 7 steps
Application Provider — 2 steps
Model Provider — 3 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Asset returnsHRS-05

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 6 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Employment TerminationHRS-06

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 3 steps
Cloud Service Provider — 6 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Employment Agreement ProcessHRS-07

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Employment Agreement ContentHRS-08

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 4 steps
Cloud Service Provider — 4 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Personnel Roles and ResponsibilitiesHRS-09

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Non-Disclosure AgreementsHRS-10

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 1 step

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Security Awareness TrainingHRS-11

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 6 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Personal and Sensitive Data Awareness and TrainingHRS-12

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 11 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Compliance User ResponsibilityHRS-13

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 10 steps
Cloud Service Provider — 6 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

AI Competency TrainingHRS-14

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 11 steps
Cloud Service Provider — 6 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

AI Acceptable UseHRS-15

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 4 steps
Application Provider — 5 steps
Model Provider — 5 steps
Orchestrated Services Provider — 5 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Standard names and gap levels shown; the specific clause references and full control text are available to the owner.

Skill pool — HRS

Detecting Deepfake Audio In Vishing Attacks